Knowledge Base::DBSA:2016-05271

Views

Disclaimer: as technology changes, advisories may become out of date or may no longer be relevant, please refer to the "Date" section of the header to be sure the advisory is recent as pertains to your situation.

Description

MySpace is a social networking platform website created for users to communicate, recent iterations of the website have been targeted toward the independent music scene. On 27 May 2016 it has been reported that the backend database of the site had been compromised and analyzed by the attackers who indicate 427 million records are in their posession. Records contain usernames, hashed passwords that are not salted (making it easy to use a rainbow table attack) and email addresses.

Digibase has not directly observed the compromised records, so this is unconfirmed at this point in time, but users should deploy standard methodologies.

Mitigation/Solution

Users should change their Myspace passwords on a rolling basis to temporary passwords, once immediately and then again at 1 weeks. After 2 weeks users may reset to a more longterm password. Users should also ensure that their password is not shared among other sites, to which those passwords will also need to be reset.

Users should also be highly suspicious of any contacts via email and use non-email methods to verify legitimacy of such email. Password resets should only be performed through known good links.